The vulnerability uses a flaw in the RTSP (Real Time Streaming Protocol) handling part of the code. If a user were to retrieve a streaming video that contained more than 256 bytes in the "src" portion of the URL, this would then compromise the machine. A successful attack then allows malicious code to be processed on the user's computer. No word yet on a patch.
Source:
Secunia
Written by: Dave Horvath @ 2 Jan 2007 10:34